XYGATE Merged Audit Reference Manual

Table Of Contents
XYGATE Merged Audit
®
Reference Manual
Glossary
XYPRO Technology Corporation 306 Proprietary and Confidential
Data Selection Criteria
Data Selection Criteria is used to select audit events based on the contents of the
normalized data record. Every field that is utilized for a given target product is available
for generating an ALERT or ACTION in a Filter. For example, if you wish to act on
failed attempts to access files:
Use the AUDIT.OUTCOME column to select audit records where this field
indicates a denial.
Use the AUDIT.OBJECTTYPE column to select audit records where this field
indicates that it is related to file access.
Refer to Chapter 3, “Configuring Filters and the FILTERS Filestarting on page 39 for
more information.
Discover Command File
Refer to MOVER Creation Command File on page 313.
DISCOVER File
The DISCOVER file contains configuration information about your MOVERs. It is
created and maintained by XMA_MANAGER. Do not alter this file.
DISCOVRA Files
The DISCOVRA file contains configuration information about your Alert-Only
MOVERs. It is created and maintained by XMA_MANAGER. Do not alter this file.
DTDLL File
The Data Transformation dll is used by the APPMOVE program to translate data from
the iTP Secure WebServer audits into a format compatible with XMA audit data.
EMSBUILD Macro
A macro to build the template file based on the system templates and the EMSTEMP
file.
EMSDDL File
The DDL layout for the XMA’s EMS messages.
EMSTEMP File
The TEMPLATE layout for XYGATEMA’s EMS messages.